Nothing Chats stores messages in plaintext

Made a thread last night about how Nothing Chats was found to send login credentials over HTTP without encryption but it gets even worse, it stores every message, picture, video and contact vcard in a publicly accessible database once again in plaintext.
https://9to5google.com/2023/11/18/nothing-chats-sunbird-unencrypted-data-privacy-nightmare/

  1. 3 weeks ago
    Anonymous

    never heard of it but who gives a shit? its not like you can trust any messanging software

    • 3 weeks ago
      Anonymous

      It let you send iMessages from a Nothing phone by using a Mac Mini server farm.

  2. 3 weeks ago
    Anonymous

    Apple is adding RCS support to iMessage; no one cares about this anymore.

    • 3 weeks ago
      Anonymous

      even if pictures and videos no longer look like dogshit teenagers and women are still going to whine about green bubbles

      • 3 weeks ago
        Anonymous

        *INTELLIGENT* teenagers and women

        • 3 weeks ago
          Anonymous

          oxymorons are welcome here.

    • 3 weeks ago
      Anonymous

      That one Google app that does RCS does the same thing. Oh sure the data in transit is end to end encrypted but since only Google and OEMs can actually implement RCS on Android you're still stuck with a bunch of proprietary apps that send everything shown on your screen to Google anyway.
      But we can't do anything about it because Google won't open up its API so it can continue to siphon backdoored chat data and because of RCS is now the industry standard.
      THEORETICALLY one can make an RCS application without google but it requires writing an android service and that's not worth the effort. Or at least it wasn't, until now, that Apple has just gone and made RCS mandatory.

      It let you send iMessages from a Nothing phone by using a Mac Mini server farm.

      It's just Sunbird, so it's really any android phone, but they agreed to exclusively support Nothing phones as a beta test group first in exchange for money from Nothing.

    • 3 weeks ago
      Anonymous

      This will probably actually make RCS the standard since before the only widely available RCS app was Google's closed API implementation with a bunch of proprietary shit on top which is quite ironic because of how much Google was banging the make RCS standard drum.

      That one Google app that does RCS does the same thing. Oh sure the data in transit is end to end encrypted but since only Google and OEMs can actually implement RCS on Android you're still stuck with a bunch of proprietary apps that send everything shown on your screen to Google anyway.
      But we can't do anything about it because Google won't open up its API so it can continue to siphon backdoored chat data and because of RCS is now the industry standard.
      THEORETICALLY one can make an RCS application without google but it requires writing an android service and that's not worth the effort. Or at least it wasn't, until now, that Apple has just gone and made RCS mandatory.
      [...]
      It's just Sunbird, so it's really any android phone, but they agreed to exclusively support Nothing phones as a beta test group first in exchange for money from Nothing.

      Google's database at least isn't publicly accessible

      • 3 weeks ago
        Anonymous

        That one Google app that does RCS does the same thing. Oh sure the data in transit is end to end encrypted but since only Google and OEMs can actually implement RCS on Android you're still stuck with a bunch of proprietary apps that send everything shown on your screen to Google anyway.
        But we can't do anything about it because Google won't open up its API so it can continue to siphon backdoored chat data and because of RCS is now the industry standard.
        THEORETICALLY one can make an RCS application without google but it requires writing an android service and that's not worth the effort. Or at least it wasn't, until now, that Apple has just gone and made RCS mandatory.
        [...]
        It's just Sunbird, so it's really any android phone, but they agreed to exclusively support Nothing phones as a beta test group first in exchange for money from Nothing.

        what's stopping careers from implementing RCS E2E on their servers now that apple is on it too? the reason they didn't before was because no one used it, not because they couldn't.

        • 3 weeks ago
          Anonymous

          RCS doesn't include E2EE in the standard. What Google does is a proprietary extension: https://www.gstatic.com/messages/papers/messages_e2ee.pdf
          It's unlikely Apple will adopt it. They're more likely to tell their users iMessage is the only secure way to chat. Also, I doubt the green bubble is gonna go away, it must be singlehandedly responsible for like 50% of their sales.

          • 3 weeks ago
            Anonymous

            >https://www.gstatic.com/messages/papers/messages_e2ee.pdf
            signal protocol is not google's, it can easily be implemented in third party clients. what i'm wondering is if google federates with other key servers for it

            • 3 weeks ago
              Anonymous

              No. Google's Messages app will only talk to Google's key server, and Google's key server will only talk to Google's Messages app.
              You probably can't even build third party clients as it stands now, not without violating the DMCA or some shit.
              Apple would have to work with them to support key exchange between Messages and iMessage, which, come on, that's not gonna happen.

              • 3 weeks ago
                Anonymous

                just because it only talks to google servers does not mean anything, do you even understand how federation works? i'm asking if google servers federate with other key servers, not if google messages client apps talk to other servers

              • 3 weeks ago
                Anonymous

                The only other players in this space are Signal, WhatsApp and Apple, and they're all operating walled gardens with no intention to federate, so no.

              • 3 weeks ago
                Anonymous

                cell carriers run federated rcs services and they have everything to gain by running their own key servers and federating those

              • 3 weeks ago
                Anonymous

                wrong.
                the last US carrier switched recently to Google's RCS service (Jibe) because you cannot simple federate with Google's RCS servers.
                E2E in RCS only exists as a proprietary Google extension.
                https://www.engadget.com/att-starts-using-googles-jibe-platform-for-rcs-messages-220258243.html

              • 3 weeks ago
                Anonymous

                Samsung Messages supports RCS on Samsung phones. Not sure if it uses any Google servers, it might, but there is an option for third parties to create other clients that have end to end encryption. Even WhatsApp has it so it is basically industry standard.

              • 3 weeks ago
                Anonymous

                I think Samsung made a deal with Google to use their RCS implementation in Samsung Messages.

              • 3 weeks ago
                Anonymous

                It goes through Play Services using a private API.

              • 3 weeks ago
                Anonymous

                >Even WhatsApp has it so it is basically industry standard.
                Samsung Messages has no E2EE.
                Google Messages only got group E2EE a few months ago.
                meanwhile WhatsApp had E2EE since ages.

    • 3 weeks ago
      Anonymous

      The RCS they agreed to implement doesn't have end to end encryption

      • 3 weeks ago
        Anonymous

        Which is Google's fault, by the way. Google RCS isn't standard RCS and no one can even implement it without Google's permission.

  3. 3 weeks ago
    Anonymous

    Interesting, almost makes you think it was designed just to push Apple into adopting RCS. Google didn't want the vulnerability, push it onto the new kid on the block who's retarded, Chinese and Nigerian hackers get their loot of fresh logins and contacts, everyone wins. It is almost too perfect. Really activates the almonds.

    • 3 weeks ago
      Anonymous

      You are either retarded or a literal child if you think Nothing's announcement had ANYTHING to do with Apple adopting RCS

      • 3 weeks ago
        Anonymous

        Not to mention that Apple announced RCS before this app even launched.

  4. 3 weeks ago
    Anonymous

    lol they didn't last long

    • 3 weeks ago
      Anonymous

      >fix several bugs
      The app is fundamentally broken, they pretty much need to rewrite everything to make it not have swiss cheese security.

  5. 3 weeks ago
    Anonymous

    yikes

  6. 3 weeks ago
    Anonymous

    >From the cons that brought you OnePlus
    No shit. It's all on some Mac mini server farm. Literal student tier shit. Use beeper like a normal person or just stick to Signal.
    I Messages is black box nonsense.

  7. 3 weeks ago
    Anonymous

    I still don't understand the hype behind anything Nothing makes, they're all shitty products that look cool for 10 seconds

    • 3 weeks ago
      Anonymous

      It's simple: All the hype is just marketing that Nothing paid for.

  8. 3 weeks ago
    Anonymous

    why are reviewers going crazy over nothing? it just seems like some shitty chinese android phone with lights on the back
    >so innovative

    • 3 weeks ago
      Anonymous

      Unihertz makes a much cheaper phone with that gimmick and on top of that it has RGB lights.

      • 3 weeks ago
        Anonymous

        Too bad it's 4G only.

        • 3 weeks ago
          Anonymous

          It also lacks wireless charging

    • 3 weeks ago
      Anonymous

      It's exactly a shitty Chinese android phone with lights, except it's by a British company now so it's suddenly attractive to Americans who are completely afraid of Chinese things.

    • 3 weeks ago
      Anonymous

      >why are reviewers going crazy over nothing?
      Because Carl Pei was friends with a lot of these influencers during his OnePlus, so he's calling in favors and paying them to artificially hype the phone. No one is genuinely hyping this disco-light chinkshit.

  9. 3 weeks ago
    Anonymous

    Never heard of it. What makes it better than Signal or Telegram?

    • 3 weeks ago
      Anonymous

      iMessage support so you can have blue bubbles. The color of your chat bubbles is apparently such a big deal here in burgerland that it warrants several hacky workarounds such as AirMessage, BlueBubbles, Beeper and now this.

      • 3 weeks ago
        Anonymous

        >colour of your chat bubbles
        I don't get it. Who is reading your text messages for it to matter? I've been able to change the colours on Android for as long as I can remember... 10+ years?

        • 3 weeks ago
          Anonymous

          Women with iPhones

          • 3 weeks ago
            Anonymous

            >woman
            Ah. Makes sense now.

        • 3 weeks ago
          Anonymous

          ah i wish to be as naive as you

          • 3 weeks ago
            Anonymous

            I don't really socialize much.
            I work my job which is mostly alone.
            I come home and hit the gym, go for a run maybe.
            Start up my PC and play vidya.

            • 3 weeks ago
              Anonymous

              honestly same

              • 3 weeks ago
                Anonymous

                It can get lonely at times but it's very peaceful.
                I listen to my family members are their arbitrary problems... Who said this, who did that... Who cares in the end.

              • 3 weeks ago
                Anonymous

                a lot of times i look at other people hanging out and miss it but it just goes away when i get to go home and do whatever i want and whenever

  10. 3 weeks ago
    Anonymous

    >just MITM yourself for bluebubbles

    Androidjeets are reaching new lows

    • 3 weeks ago
      Anonymous

      >implying ijeets aren't already doing that

      • 3 weeks ago
        Anonymous

        don't confuse iMessage with your shitty messengers on Android.
        iMessage has key transparency
        https://security.apple.com/blog/imessage-contact-key-verification/

        • 3 weeks ago
          Anonymous

          >believing marketing material for closed source software

  11. 3 weeks ago
    Anonymous

    >Chinese CEO
    >A lying grifter
    lol
    every single time

Your email address will not be published. Required fields are marked *